Re: Using Views for security ?
Posted in 1993
Cynthia Leong ( cynthia@hpsgcip1.sgp.hp.com ) writes:
>
> Do you have any experience in using views for security purposes?
> If yes, please let me know :
Yes, I have used views, and our product DB Privileges supports
granting and revoking privileges on views.
> 1) How do you make use of it.
The main reason to use a view and not the table for security is to
control security at the row level. If you are granting users
access to all rows in a table, then it is best to maintain
security at the table level.
A view works well when you want a user to have access to a limited
set of rows in a table. (e.g only the rows they have entered, or
only the customers in their region.) As an example, if you wanted to
limit a sales person's access to only customers in their region you
would:
create view region_a as select * from customer where region = "A";
revoke all on customer from salesa;
grant all on region_a to salesa;
> 2) What are its limitations.
All security depends on Informix being correctly installed, controlling
access to the user and group informix, and having the permissons on your
unix devices or files for the database set correctly.
Another problem is public access. If you revoke a user's table
privilege, but still allow public access, the user can access the
table through public access. This defeats the purpose of having
row level security with views.
> 3) What are its strength
> 4) Any specific reason why you opt for views?
Row level security as in the example above.
> 5) Maintenability
The same as table level security.
Regards - Lester
#############################################################################
# Lester Knutsen lester@access.digex.net #
# Advanced DataTools Corporation Voice: 703-256-0267 #
# Providing Informix Database Tools and Consulting #
#############################################################################